CVE-2025-44203

In HotelDruid 3.0.7, an unauthenticated attacker can exploit verbose SQL error messages on creadb.php before the 'create database' button is pressed. By sending malformed POST requests to this endpoint, the attacker may obtain the administrator username, password hash, and salt. In some cases, the attack results in a Denial of Service (DoS), preventing the administrator from logging in even with the correct credentials.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:digitaldruid:hoteldruid:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:digitaldruid:hoteldruid:3.0.7:*:*:*:*:*:*:*

History

26 Jun 2025, 14:35

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-20 16:15

Updated : 2025-06-26 14:35


NVD link : CVE-2025-44203

Mitre link : CVE-2025-44203

CVE.ORG link : CVE-2025-44203


JSON object : View

Products Affected

digitaldruid

  • hoteldruid
CWE
CWE-209

Generation of Error Message Containing Sensitive Information

CWE-400

Uncontrolled Resource Consumption